cleantalk
Vulnerabilities and Security Researches

Tutor LMS – eLearning and online course solution, bc1f93ade3fce02864fa36fa0f89b6284353387a

Published on
Jan 10, 2021
Research Description
Tutor LMS &#8211; eLearning and online course solution [tutor] < 1.9.13 Tutor LMS <= 1.9.12 - Reflected Cross-Site Scripting The Tutor LMS plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 1.9.12 due to missing input and output sanitization of some user generated URLs.
Affected versions
max 1.9.13.
Status
vulnerable